[
https://issues.apache.org/jira/browse/HBASE-7367?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13534134#comment-13534134
]
Matteo Bertozzi commented on HBASE-7367:
----------------------------------------
as I've said in the jira, this is just the first step to have all the code
ready.
and the semantic of the snapshot acl is still a bit unclear.
assuming that everyone with GLOBAL ADMIN or CREATE privilege on the table can
take the snapshot.
What should the restore/clone look like?
* only GLOBAL ADMIN can clone?
* only GLOBAL admin and users with CREATE privilege can restore?
What happens to the _acl_ table?
* Restore the old (snapshotted) rights for the table?
* Keep the current one?
> Snapshot coprocessor and ACL security
> -------------------------------------
>
> Key: HBASE-7367
> URL: https://issues.apache.org/jira/browse/HBASE-7367
> Project: HBase
> Issue Type: Sub-task
> Components: Client, master, regionserver, snapshots, Zookeeper
> Reporter: Matteo Bertozzi
> Assignee: Matteo Bertozzi
> Priority: Minor
> Fix For: hbase-6055, 0.96.0
>
> Attachments: HBASE-7367-v0.patch
>
>
> Currently snapshot don't care about ACL...
> and in the first draft snapshots should be disabled if the ACL coprocessor is
> enabled.
> After the first step, we can discuss how to handle the snapshot/restore/clone.
> Is saving and restoring the _acl_ related rights, the right way? maybe after
> 3 months we don't want to give the access the guys listed in the old _acl_...
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira